OpenText kayıtları
opentext üreticisine ait 137 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %2,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-787 Out-of-bounds Write17
- CWE-20 Improper Input Validation9
- CWE-287 Improper Authentication8
- CWE-611 Improper Restriction of XML External Entity Reference5
- CWE-125 Out-of-bounds Read5
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
137 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
47Planlayın | CVE-2017-5586Kavram kanıtı | OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java opentext · documentum d2 · CWE-20 | Kritik9,8 | — | %25,3 | 22 Şub 2017 |
40Planlayın | CVE-2022-45926İstismar yok | An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).opentext · opentext extended ecm · CWE-918 | Yüksek8,8 | — | %17,0 | 18 Oca 2023 |
40Planlayın | CVE-2016-2002İstismar yok | The validateAdminConfig handler in the Analytics Management Console in HPE Vertica 7.0.x before 7.0.2.12, 7.1.x before 7.1.2-12, and 7.2.x bopentext · vertica · CWE-77 | Kritik9,8 | — | %3,1 | 20 Nis 2016 |
40Planlayın | CVE-2017-5802İstismar yok | A Remote Gain Privileged Access vulnerability in HPE Vertica Analytics Platform version v4.1 and later was found.opentext · vertica | Kritik9,8 | — | %2,3 | 15 Şub 2018 |
39İzleyin | CVE-2017-14759İstismar yok | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) opentext · document sciences xpression · CWE-611 | Kritik9,8 | — | %1,3 | 2 Eki 2017 |
39İzleyin | CVE-2024-1147İstismar yok | Weak Access Control - Arbitrary file downloadopentext · pvcs version manager · CWE-287 | Kritik9,8 | — | %0,7 | 21 Mar 2024 |
39İzleyin | CVE-2024-1148İstismar yok | Weak Access Control - Arbitrary file uploadopentext · pvcs version manager · CWE-287 | Kritik9,8 | — | %0,7 | 21 Mar 2024 |
39İzleyin | CVE-2022-35898İstismar yok | OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation.opentext · bizmanager · CWE-287 | Kritik9,8 | — | %0,6 | 1 May 2023 |
39İzleyin | CVE-2024-1811İstismar yok | OpenText ArcSight Platform Remote Vulnerabilityopentext · arcsight platform | Kritik9,8 | — | %0,6 | 20 Mar 2024 |
39İzleyin | CVE-2023-7248İstismar yok | OpenText Vertica Management console might be prone to bypass via crafted requestsopentext · vertica · CWE-20 | Kritik9,8 | — | %0,3 | 15 Mar 2024 |
39İzleyin | CVE-2023-38535İstismar yok | Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2.opentext · exceed turbox · CWE-321 | Kritik9,8 | — | %0,3 | 13 Mar 2024 |
39İzleyin | CVE-2024-6359İstismar yok | Privilege escalation vulnerabilityopentext · arcsight intelligence · CWE-269 | Kritik9,8 | — | %0,3 | 6 Ağu 2024 |
38İzleyin | CVE-2017-15276Kavram kanıtı | OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an aopentext · documentum content server · CWE-22 | Yüksek8,8 | — | %9,5 | 13 Eki 2017 |
37İzleyin | CVE-2017-15012Kavram kanıtı | OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 does not properly validate the input of the PUT_FILEopentext · documentum content server · CWE-20 | Yüksek8,8 | — | %7,8 | 13 Eki 2017 |
37İzleyin | CVE-2017-15013Kavram kanıtı | OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an aopentext · documentum content server · CWE-269 | Yüksek8,8 | — | %6,6 | 13 Eki 2017 |
36İzleyin | CVE-2017-7221Kavram kanıtı | OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to opentext · documentum content server · CWE-89 | Yüksek8,8 | — | %4,2 | 25 Nis 2017 |
36İzleyin | CVE-2017-14758Kavram kanıtı | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) opentext · document sciences xpression · CWE-89 | Yüksek8,8 | — | %2,7 | 2 Eki 2017 |
36İzleyin | CVE-2017-7220İstismar yok | OpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an unauthorized "UPDATEopentext · documentum content server · CWE-20 | Yüksek8,8 | — | %2,0 | 20 Nis 2017 |
36İzleyin | CVE-2017-5585İstismar yok | OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and return_top_results_rowopentext · documentum content server · CWE-74 | Yüksek8,8 | — | %2,0 | 22 Şub 2017 |
36İzleyin | CVE-2017-14757Kavram kanıtı | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) opentext · document sciences xpression · CWE-89 | Yüksek8,8 | — | %1,9 | 2 Eki 2017 |
36İzleyin | CVE-2022-45923İstismar yok | An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).opentext · opentext extended ecm · CWE-502 | Yüksek8,8 | — | %1,9 | 18 Oca 2023 |
36İzleyin | CVE-2022-45927İstismar yok | An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).opentext · opentext extended ecm · CWE-639 | Yüksek8,8 | — | %1,9 | 18 Oca 2023 |
36İzleyin | CVE-2022-45928İstismar yok | A remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).opentext · opentext extended ecm · CWE-94 | Yüksek8,8 | — | %1,7 | 18 Oca 2023 |
36İzleyin | CVE-2019-17082İstismar yok | Insufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass.opentext™ · accurev · CWE-522 | Kritik9,0 | — | %0,5 | 26 Kas 2024 |
35İzleyin | CVE-2022-45925İstismar yok | An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).opentext · opentext extended ecm · CWE-200 | Yüksek7,5 | — | %16,9 | 18 Oca 2023 |
- CVE-2017-558647Planlayın
OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java
KritikCVSS 9,8Kavram kanıtıEPSS %25opentext · documentum d222 Şub 2017
- CVE-2022-4592640Planlayın
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).
YüksekCVSS 8,8İstismar yokEPSS %17opentext · opentext extended ecm18 Oca 2023
- CVE-2016-200240Planlayın
The validateAdminConfig handler in the Analytics Management Console in HPE Vertica 7.0.x before 7.0.2.12, 7.1.x before 7.1.2-12, and 7.2.x b
KritikCVSS 9,8İstismar yokEPSS %3opentext · vertica20 Nis 2016
- CVE-2017-580240Planlayın
A Remote Gain Privileged Access vulnerability in HPE Vertica Analytics Platform version v4.1 and later was found.
KritikCVSS 9,8İstismar yokEPSS %2opentext · vertica15 Şub 2018
- CVE-2017-1475939İzleyin
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well)
KritikCVSS 9,8İstismar yokEPSS %1opentext · document sciences xpression2 Eki 2017
- CVE-2024-114739İzleyin
Weak Access Control - Arbitrary file download
KritikCVSS 9,8İstismar yokEPSS %1opentext · pvcs version manager21 Mar 2024
- CVE-2024-114839İzleyin
Weak Access Control - Arbitrary file upload
KritikCVSS 9,8İstismar yokEPSS %1opentext · pvcs version manager21 Mar 2024
- CVE-2022-3589839İzleyin
OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation.
KritikCVSS 9,8İstismar yokEPSS %1opentext · bizmanager1 May 2023
- CVE-2024-181139İzleyin
OpenText ArcSight Platform Remote Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1opentext · arcsight platform20 Mar 2024
- CVE-2023-724839İzleyin
OpenText Vertica Management console might be prone to bypass via crafted requests
KritikCVSS 9,8İstismar yokEPSS %0opentext · vertica15 Mar 2024
- CVE-2023-3853539İzleyin
Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2.
KritikCVSS 9,8İstismar yokEPSS %0opentext · exceed turbox13 Mar 2024
- CVE-2024-635939İzleyin
Privilege escalation vulnerability
KritikCVSS 9,8İstismar yokEPSS %0opentext · arcsight intelligence6 Ağu 2024
- CVE-2017-1527638İzleyin
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an a
YüksekCVSS 8,8Kavram kanıtıEPSS %9opentext · documentum content server13 Eki 2017
- CVE-2017-1501237İzleyin
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 does not properly validate the input of the PUT_FILE
YüksekCVSS 8,8Kavram kanıtıEPSS %8opentext · documentum content server13 Eki 2017
- CVE-2017-1501337İzleyin
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an a
YüksekCVSS 8,8Kavram kanıtıEPSS %7opentext · documentum content server13 Eki 2017
- CVE-2017-722136İzleyin
OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to
YüksekCVSS 8,8Kavram kanıtıEPSS %4opentext · documentum content server25 Nis 2017
- CVE-2017-1475836İzleyin
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well)
YüksekCVSS 8,8Kavram kanıtıEPSS %3opentext · document sciences xpression2 Eki 2017
- CVE-2017-722036İzleyin
OpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an unauthorized "UPDATE
YüksekCVSS 8,8İstismar yokEPSS %2opentext · documentum content server20 Nis 2017
- CVE-2017-558536İzleyin
OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and return_top_results_row
YüksekCVSS 8,8İstismar yokEPSS %2opentext · documentum content server22 Şub 2017
- CVE-2017-1475736İzleyin
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well)
YüksekCVSS 8,8Kavram kanıtıEPSS %2opentext · document sciences xpression2 Eki 2017
- CVE-2022-4592336İzleyin
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).
YüksekCVSS 8,8İstismar yokEPSS %2opentext · opentext extended ecm18 Oca 2023
- CVE-2022-4592736İzleyin
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).
YüksekCVSS 8,8İstismar yokEPSS %2opentext · opentext extended ecm18 Oca 2023
- CVE-2022-4592836İzleyin
A remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).
YüksekCVSS 8,8İstismar yokEPSS %2opentext · opentext extended ecm18 Oca 2023
- CVE-2019-1708236İzleyin
Insufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass.
KritikCVSS 9,0İstismar yokEPSS %0opentext™ · accurev26 Kas 2024
- CVE-2022-4592535İzleyin
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).
YüksekCVSS 7,5İstismar yokEPSS %17opentext · opentext extended ecm18 Oca 2023